AMENDMENTS TO THE CLAIMS; 

This listing of the claims will replace all prior versions and listings of the claims in 
the present application: 

LISTING OF CLAIMS : 

1 . (Currently Amended) A method for monitoring events generated on at least one 
computer system, said method comprising the steps of: 

(a) monitoring a set of event data generated on said at least one system; 

(b) recording said set of event data in a database; 

(c) interrogating said database to thereby select alert event data from said set of event 

data according to a predefined set of rules;-and 

(d) reading said alert event data and issuing an appropriate action due to said 

generated event, said action issued according to said predefined set of rulesi 
and 

(e) determining said action response based upon said pre-defined set of rules and 

based upon a weighting factor applied to recorded historical outcomes for 
monitored events . 

2. (Original) A method as claimed in claim 1, wherein said action response occurs in 
real-time as a user interacts with said computer system. 

3. (Currently Amended) A method as claimed in claim 2, wherein said method fiirther 
comprises the step of: (ef) issuing said action response to said at least one computer system to 
prevent further interaction of said user with said computer system. 

4. (Cancelled) 

5. (Original) A method as claimed in claim 1, wherein said set of event data is 
monitored from the interaction of one or more users interaction with one or more computers 
on a network. 

6. (Original) A method as claimed in claim 5. wherein said monitored set of event 
data is monitored from a number of sources on said computer network, including any one or 
more of the following network components: the application program layer; the transport 
layer; security layer; operating system. 

7. (Original) A method as claimed in claim 6, wherein said application program layer 
includes any one or more the following: customer relationship management, enterprise 
resource planning; customer billing. 
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8. (Original) A method as claimed in claim 6, wherein said operating system includes 
any one or more but not limited to the following: database application server; LAN; router; 
PABX; telephone network; network server. 

9. (Original) A method as claimed in claim 6, wherein said security layer includes any 
one or more but not limited to the following: firewalls; card-swipe facility access; close- 
circuit security television. 

1 0. (Original) A method as claimed in claim 1 . wherein said method further includes 
the step of: (g) permitting an authorised user to interactively define said set of rules in step 
(c). 

1 1 . (Original) A method as claimed in claim 1 0, wherein said authorised user can 
interactively define and/or amend said set of rules in step (c) using a user graphical interface. 

12. (Original) A method as claimed in claim 11, wherein said graphical interface is a 
web browser. 

13. (Cancelled) 

14. (Original) A method as claimed in claim 1, wherein one or more agent programs 
are provided on at least one computer of said computer system to thereby monitor said set of 
event data. 

15. (Original) A method as claimed in claim 1, wherein said event data is recorded in 
a relational database. 

16. (Original) A method as claimed in claim 15, wherein said event data is assigned a 
unique log identifier in said database to identify the record of each event. 

17. (Original) A method as claimed in claim 16, wherein said unique log identifier is 
used to correlated as a single event, a multiplicity of events generated on one or more 
computer systems. 

18. (Original) A method as claimed in claim 1, wherein a report is generated to report 
said recorded said set of event data. 

19. (Original) A method as claimed claim 1, wherein said appropriate action is a 
message sent to a network administrator. 

20. (Original) A method as claimed in claim 19, wherein said appropriate action is a 
message sent to an authorised person. 

21 . (Original) A method as claimed in claim 20, wherein said message is any one or 
more of the following message types: electronic mail; SMS text massaging; audio signal; 
telephone call; pagers; WAP appliances. 



NYOI 1087243 vl 



3 



22. (Currently Amended) A computer memory storing thereon an application program 
for controlling the execution of a processor to monitor events generated on at least one 
computer system, the computer program controlling the processor to: monitor a set of event 
data generated on at least one computer system; record said set of event data in a database; 
interrogate said database to thereby select alert event data from said set of event data 
according to a predefined set of rules; aad-read said alert event data and issue an appropriate 
action due to said generated event on said computer system, said action issued according to 
said predefined set of rules : and determine said action response based upon said pre-defined 
set of rules and based upon a weighting factor applied to recorded historical outcomes for 
monitored events . 

23. (Original) A computer memory as claimed in claim 22, w^herein said action 
response occurs in real-time. 

24. (Original) A computer memory as claimed in claim 22, wherein the computer 
program fiarther controls the processor to issue said action response to said at least one 
computer system to prevent further interaction a user of said computer. 

25. (Cancelled) 

26. (Original) A computer memory as claimed in claim 22, wherein said set of event 
data is monitored from events generated by one or more computers on a network. 

27. (Original) A computer memory as claimed in claim 26, wherein said monitored 
set of event data is monitored from a number of sources on said computer network, including 
any one or more of the following network components: the application program layer; the 
transport layer; security layer; operating system. 

28. (Original) A computer memory as claimed in claim 27, wherein said application 
program layer includes any one or more of the following customer relationship management, 
enterprise resource planning; customer billing. 

29. (Original) A computer memory as claimed in claim 27, wherein said operating 
system includes any one or more of the following: database application server; LAN; router; 
PABX; telephone network; network server. 

30. (Original) A computer memory as claimed in claim 27, wherein said security layer 
includes any one or more of the following, firewalls; card-swipe facility access; close-circuit 
security television. 

3 1 . (Original) A computer memory as claimed in claim 22, wherein said computer 
program fiirther controls the processor to permit an authorised user to interactively define 
said set of rules. 
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32. (Original) A computer memory as claimed in claim 31, wherein said authorised 
user can define and/or amend said set of rules in step using a user graphical interface. 

33. (Original) A computer memory as claimed in claim 32, wherein said graphical 
interface is a web browser. 

34. (Cancelled) 

35. (Original) A computer memory as claimed in claim 22, wherein one or more agent 
programs are provided on each computer system to monitor said set of event data. 

36. (Original) A computer memory as claimed in claim 22, wherein said event data is 
recorded in a relational database. 

37. (Original) A computer memory as claimed in claim 36, wherein said event data is 
assigned a unique log identifier in said database to identify the record of each event. 

38. (Original) A computer memory as claimed in claim 37, wherein said unique log 
identifier is used to correlated as a single event, a multiplicity of events generated on one or 
more computer systems. 

39. (Original) A computer memory as claimed in claim 22, wherein a report is 
generated to report said recorded set of event data. 

40. (Original) A computer memory as claimed claim 22, wherein said appropriate 
action is a message sent to a network administrator. 

41 . (Original) A computer memory as claimed in claim 40, wherein said appropriate 
action is a message sent to an authorised person, 

42. (Original) A computer memory as claimed in claim 41, wherein said message is 
any one or more of the following message types: electronic mail; SMS text massaging; audio 
signal; telephone call; pagers; WAP appliances. 

43. (Currently Amended) A monitoring system for monitoring events generated on at 
least one computer system, said monitoring system comprising 

one ore more agent programs for monitoring a set of event data generated on said at 

least one computer system; 
a database for recording said set of event data in a database, said database adapted to 

be interrogated to thereby select alert event data from said set of event data 

according to a predefined set of rules; and 
action generation means for reading said alert event data and issuing an appropriate 

action to said generated event on said computer system, said action being 

issued according to said predefined set of rules and wherein the action is 
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determined based upon said pre-defined set of rules and based upon a 
weighting factor applied to recorded historical outcomes for monitored events . 

44. (Original) A monitoring system as claimed in claim 43, wherein said action 
generation means issues said action response to said at least one computer system to prevent 
interaction of a user with said computer. 

45. (Cancelled) 

46. (Original) A monitoring system as claimed in claim 43, wherein an authorised 
user is able to define said set of rules. 

47. -55. (Cancelled) 
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